Security

How we protect customer and guest data.

Data in transit and at rest

  • All traffic between client devices and Vidimo is encrypted with TLS 1.2 or above.
  • Customer data is stored encrypted at rest in our managed Postgres instance and our object storage buckets.
  • Backups inherit the same encryption-at-rest guarantees and are tested for restorability on a recurring schedule.

Access control

  • Multi-factor authentication is required for every member of the Nuage team on Google Workspace, GitHub, Vercel, and AWS.
  • Production access follows least privilege — engineers request short-lived elevated credentials per task instead of holding standing admin access.
  • Application-layer access is tenanted by property: cross-tenant reads are blocked at the query layer by PowerSync sync rules and at the API layer by property-membership checks.

Vulnerability management

  • Continuous dependency scanning runs on every commit through GitHub Advanced Security.
  • Quarterly third-party vulnerability scans are scheduled and the results are triaged within five business days of delivery.
  • Critical CVEs in dependencies we ship to production are patched within 48 hours of public disclosure where a fix is available; high-severity within seven days; medium within 30 days.

Incident response

We maintain an internal incident-response runbook that defines on-call rotation, severity levels, communication templates, and post-mortem expectations. Customers affected by a security incident will be notified without undue delay and, where applicable, within the timeframes required by the GDPR.

Sub-processors

The current list of sub-processors that may handle customer or guest data on our behalf is published at Sub-processors. We update this list when we add, replace, or remove a sub-processor.

Compliance roadmap

Vidimo is GDPR-aligned by design. We are working towards SOC 2 Type I attestation; a Type II window will follow once Type I controls have been operational for the required period. Customers with specific compliance questions can request our current security questionnaire responses.

Report a vulnerability

We take reports from external researchers seriously. Please contact us — we will acknowledge receipt within two business days, agree on coordinated disclosure timing, and credit researchers in our release notes where requested.

Email: security@vidimo.app